Aller au contenu

Fiche vulnérabilité

CVE-2025-63388 : faille critique langgenius dify (CVSS 9.1)

Description

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests. NOTE: the Supplier disputes this, providing the rationale of "sending requests with credentials does not provide any additional access compared to unauthenticated requests."

En bref

Sévérité
Critique (CVSS 9.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
18 déc. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • langgenius dify

Références

Rechercher une autre vulnérabilité dans la base CVE